CVE-2014-8566
mod_auth_mellon: remote memory disclosure flaw
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."
El modulo mod_auth_mellon anterior a 0.8.1 permite a atacantes remotos obtener información sensible o causar una denegación de servicio (fallo en la segmentación) a través de vectores sin especificar, relacionado con un 'desbordamiento de sesión' que implica 'la superposición de sesiones en la memoria'.
An information disclosure flaw was found in mod_auth_mellon's session handling that could lead to session overlapping in memory. A remote attacker could potentially use this flaw to obtain data from another user's session.
mod_auth_mellon provides a SAML 2.0 authentication module for the Apache HTTP Server. An information disclosure flaw was found in mod_auth_mellon's session handling that could lead to sessions overlapping in memory. A remote attacker could potentially use this flaw to obtain data from another user's session. It was found that uninitialized data could be read when processing a user's logout request. By attempting to log out, a user could possibly cause the Apache HTTP Server to crash.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-10-31 CVE Reserved
- 2014-11-05 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://linux.oracle.com/errata/ELSA-2014-1803.html | X_refsource_confirm | |
http://secunia.com/advisories/62094 | Third Party Advisory | |
http://secunia.com/advisories/62125 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/UNINETT/mod_auth_mellon/releases/tag/v0.8.1 | 2019-12-27 | |
https://postlister.uninett.no/sympa/arc/modmellon/2014-11/msg00000.html | 2019-12-27 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2014-1803.html | 2019-12-27 | |
https://access.redhat.com/security/cve/CVE-2014-8566 | 2014-11-05 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1157281 | 2014-11-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Uninett Search vendor "Uninett" | Mod Auth Mellon Search vendor "Uninett" for product "Mod Auth Mellon" | <= 0.8.0 Search vendor "Uninett" for product "Mod Auth Mellon" and version " <= 0.8.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Linux Search vendor "Oracle" for product "Linux" | 6 Search vendor "Oracle" for product "Linux" and version "6" | - |
Affected
|